
Cybersecurity Engineer, Cryptography
- KMS
- PKI
- mTLS
- NIST
- FIPS
- PCI DSS
- SOC2
- TLS
- AWS
- Rust
Client: US technology company (digital identity and payments infrastructure) Β·Location: remote, LATAM, US Eastern overlap Β·Level: senior Β·Engagement: full-time contractor
You will own applied cryptography across the product: key management, protocol design review and the migration plan to post-quantum algorithms.
What you will do
Design and operate key management on HSMs and cloud KMS, including rotation, escrow and ceremonies
Review protocol and feature designs for correct use of encryption, signatures and key exchange
Run PKI: certificate authorities, issuance automation and mTLS between services
Build the crypto inventory and lead the roadmap to NIST post-quantum standards (ML-KEM, ML-DSA)
Maintain internal crypto libraries and guidance so product teams do not roll their own
Support audits and certifications such as FIPS 140-3, PCI DSS and SOC 2
What you bring
6+ years in security engineering, 3+ focused on applied cryptography
Solid command of modern primitives and protocols (AES-GCM, ECC, TLS 1.3, Noise, JOSE)
Hands-on HSM and KMS experience (Thales, AWS CloudHSM, AWS KMS or equivalent)
Coding in Go, Rust or C, with secure coding and code review experience
Ability to explain cryptographic risk to non-specialists in English
Nice to have
Threshold signatures, MPC or zero-knowledge proof experience
Degree or research background in cryptography
Contributions to open-source crypto libraries
Cybersecurity Engineer, Cryptography Β· Itmates